EIP-2026-118113

PRE-CVE

Winamp 5.6 - 'MIDI Parser' Arbitrary Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118113. PoCs published by Kryptos Logic.

AI-analyzed exploit summary This is a technical writeup detailing a buffer overflow vulnerability in Winamp's MIDI parser, specifically in the serialization of 32-bit integers into MIDI timestamps. The vulnerability allows an attacker to write one byte outside an 8-byte buffer, potentially leading to arbitrary code execution.

Description

Winamp 5.6 - 'MIDI Parser' Arbitrary Code Execution

Exploits (1)

exploitdb WRITEUP VERIFIED
by Kryptos Logic · textlocalwindows
https://www.exploit-db.com/exploits/15706

This is a technical writeup detailing a buffer overflow vulnerability in Winamp's MIDI parser, specifically in the serialization of 32-bit integers into MIDI timestamps. The vulnerability allows an attacker to write one byte outside an 8-byte buffer, potentially leading to arbitrary code execution.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Winamp 5.6, Winamp 5.581
No auth needed
Prerequisites: Crafted MIDI file with specific timestamp values
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026